pm
Warn
Audited by Gen Agent Trust Hub on Aug 4, 2026
Risk Level: MEDIUMPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill package includes 8 large, unreferenced markdown files (e.g., architecture-patterns.md, security-best-practices.md) that contain over 1,200 repetitive blocks of technical jargon completely unrelated to the skill's stated purpose of Project Management. This is a classic 'Context Stuffing' technique intended to displace instructions or safety guardrails in the model's context.
- [PROMPT_INJECTION]: The skill's description uses high keyword density for trigger phrases, suggesting an 'intent hijacking' pattern aimed at over-activating the skill across many unrelated user queries.
- [NO_CODE]: No executable code or runtime scripts are shipped with this skill; it consists entirely of markdown documentation and static reference materials.
- [SAFE]: While the skill contains code snippets (Python, Rust, TypeScript) for educational purposes within the documentation, none of these are intended for or capable of execution in the agent's environment.
Audit Metadata